Deployment Architecture

How to set up High Availability architecture from my current indexer clustering environment?

logmar5
Explorer

My current Splunk setup is a cluster of 3 indexers, one in each region. One Master, two Peers. With distributed search enabled between them. My next goal is to create High Availability Splunk environment.

If I simply run another duplicate cluster setup on backup servers, that will mean duplicating license cost and storage space.

Does anyone have any suggestions for the proper setup? Or a pointer to a good Splunk doc with details?

Thank you!

0 Karma

mahamed_splunk
Splunk Employee
Splunk Employee

Yes, we have lots of documentation on this. I suggest that you start with this

http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Aboutclusters

0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...